Business impact (BIA)
The business-process register — criticality, availability target, the systems beneath each process, and what the rating changes elsewhere.
One table, one row per business process, sorted by criticality. The question this register is opened with is comparative — which of our processes are most exposed, and what would take them down — so every axis of that comparison is a column that sorts and filters, and the name lists open inside the row.
Four criticality levels
| Level | Note |
|---|---|
| Critical | |
| Important | |
| Normal | |
| TBD | Not yet classified |
TBD is not “low”. Everywhere the rating is used, a process that has not been classified counts as more risk than one explicitly classified as normal — the same stance the product takes on every other unknown it holds.
Two time measures, and they are not the same measure
RTO — recovery time — is a property of a system, recorded in minutes, and is never folded into one figure for the process. A process resting on five systems where only one has a recorded RTO would read as “known” while four fifths of it is not. So the expanded row lists the systems that have an RTO, and names the ones that do not.
The columns
| Column | What it holds |
|---|---|
| Business process | The process name |
| Criticality | The level |
| SLA | Downtime hours allowed per year, derived from the availability target |
| Linked systems | How many systems the register associates with the process |
| Linked servers | How many servers beneath them |
| Overdue servers | How many are past their next update date, with the full update-state mix drawn behind them |
| Linked databases | How many databases |
| Network connections | How many other systems those systems actually talk to |
The last two columns are genuinely different: Linked systems is the association the register recorded, Network connections is an observed fact. Network connections, the system name list and the description are hidden by default and can be brought back; they still filter, export and can be stored in a saved view.
Expanding a row
The expanded row holds the description, the continuity pair (SLA, and RTO per system), system chips with their server and overdue counts, database chips, and a link to the Process record — where the full tree, the map, the custom fields and the uncapped lists live.
Beside them sits a warning chip counting the process's continuity gaps: no availability target recorded, no systems associated at all, or systems with no recorded RTO — each named. Facts that were recorded stay as text; the warning counts only what is missing.
A process created inside the product carries a “Created in Regulaxy” tag and can be edited. A row that came from the BIA register is not edited here.
What the rating changes elsewhere
Criticality does not stay on this screen. It is one of the five terms of the urgency score in Smart recommendations, and a system belonging to several processes takes the worst of their levels.
| Permission | What it opens |
|---|---|
bia.view | The register and the process record |
bia.edit | Editing custom fields on the record — not changing the BIA register itself |
If the BIA source has not been made available in the environment, the screen says so explicitly rather than showing an empty table.
Updated
This page is the file content/docs/en/v1/risk/bia.mdx